UIAutomator2 MCP Server
PYPI · UIAUTOMATOR2-MCP-SERVER · SCANNED SEP 20
Android mobile automation with uiautomator2. AI bot for taps, swipes, apps, XPath testing, RPA.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security49
- Malware scan not yet available for this package.Unverified
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 4 of 31 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency6
- Repository check failed: no source repository is declared. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: no license is declared. See how to fix → Fail
- Actively maintained (last published 113 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 3894 tokens (~50/item across 77 items; 77 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
- 97% of tools have a non-trivial description (not blank, and not just the tool's name).Partial
- 98% of tool parameters carry a description.Partial
- Structured output schemas are declared (45% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "purge" implies "purge" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 78 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the UIAutomator2 MCP Server server?
UIAutomator2 MCP Server runs locally as a PyPI package, launched with uvx uiautomator2-mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · uiautomator2-mcp-server
claude mcp add tanbro-uiautomator2-mcp-server -- uvx uiautomator2-mcp-server
{
"mcpServers": {
"tanbro-uiautomator2-mcp-server": {
"command": "uvx",
"args": [
"uiautomator2-mcp-server"
]
}
}
} {
"servers": {
"tanbro-uiautomator2-mcp-server": {
"command": "uvx",
"args": [
"uiautomator2-mcp-server"
]
}
}
} codex mcp add tanbro-uiautomator2-mcp-server -- uvx uiautomator2-mcp-server
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"tanbro-uiautomator2-mcp-server": {
"type": "local",
"command": [
"uvx",
"uiautomator2-mcp-server"
],
"enabled": true
}
}
} openclaw mcp add tanbro-uiautomator2-mcp-server --command uvx --arg uiautomator2-mcp-server
mcp_servers:
tanbro-uiautomator2-mcp-server:
command: "uvx"
args: ["uiautomator2-mcp-server"] {
"McpServers": {
"tanbro-uiautomator2-mcp-server": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"uiautomator2-mcp-server"
]
}
}
} assistant mcp add tanbro-uiautomator2-mcp-server -t stdio -c uvx -a uiautomator2-mcp-server
{
"mcpServers": {
"tanbro-uiautomator2-mcp-server": {
"command": "uvx",
"args": [
"uiautomator2-mcp-server"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 −3
- Stability: pass → 0.80 functional
- 19 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 −3
- Stability: pass → 0.80 functional
- 12 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/uiautomator2-mcp-server@0.3.3
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | setuptools.build_meta |
Background: Why install scripts are a supply-chain risk →
Dependencies 31 packages
| Packages resolved | 31 |
|---|---|
| Stale | 3 |
| No linked repository | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
activity_wait_appear ~53
Wait for an activity to appear.
| Name | Type | Req | Description |
|---|---|---|---|
| activity | string | yes | Name of activity to wait for. |
| serial | string | yes | Android device serial number. |
| timeout | number | yes | Maximum wait time in seconds. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | boolean | yes | – |
No examples provided.
app_auto_grant_permissions ~36
auto grant permissions
| Name | Type | Req | Description |
|---|---|---|---|
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
app_clear ~38
Stop and clear app data: pm clear
| Name | Type | Req | Description |
|---|---|---|---|
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
app_current ~24
Get current app info
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
Structured output declared, but exposes no named fields.
No examples provided.
app_info ~33
Get app info
| Name | Type | Req | Description |
|---|---|---|---|
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
Structured output declared, but exposes no named fields.
No examples provided.
app_install ~34
Install app
| Name | Type | Req | Description |
|---|---|---|---|
| data | string | yes | APK file path or url |
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
app_list ~61
List installed app package names
| Name | Type | Req | Description |
|---|---|---|---|
| filter | string | – | [-f] [-d] [-e] [-s] [-3] [-i] [-u] [--user USER_ID] [FILTER] |
| serial | string | yes | Android device serialno |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
app_list_running ~24
List running apps
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
app_start ~70
Launch application
| Name | Type | Req | Description |
|---|---|---|---|
| activity | – | – | app activity |
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
| stop | boolean | – | Stop app before starting the activity. (require activity) |
| wait | boolean | – | wait until app started. default False |
No output schema declared.
No examples provided.
app_stop ~33
Stop one application
| Name | Type | Req | Description |
|---|---|---|---|
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
app_stop_all ~34
Stop all third party applications
| Name | Type | Req | Description |
|---|---|---|---|
| excludes | – | – | apps that do now want to kill |
| serial | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
app_uninstall ~35
Uninstall an app
| Name | Type | Req | Description |
|---|---|---|---|
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
| Name | Type | Req | Description |
|---|---|---|---|
| result | boolean | yes | – |
No examples provided.
app_uninstall_all ~38
Uninstall all apps
| Name | Type | Req | Description |
|---|---|---|---|
| excludes | – | – | packages that do not want to uninstall |
| serial | string | yes | Android device serialno |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
app_wait ~56
Wait until app launched
| Name | Type | Req | Description |
|---|---|---|---|
| front | – | – | wait until app is current app |
| package_name | string | yes | package name |
| serial | string | yes | Android device serialno |
| timeout | number | – | maximum wait time seconds |
No output schema declared.
No examples provided.
clear_text ~27
Clear text in the current input field
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
click ~41
Click at specific coordinates
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
| x | integer | yes | X coordinate |
| y | integer | yes | Y coordinate |
No output schema declared.
No examples provided.
connect ~40
Connect to an Android device
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | – | Android device serial number. If empty string, connects to the unique device if only one device is connected. |
Structured output declared, but exposes no named fields.
No examples provided.
delay ~26
Delay for a specific amount of time.
| Name | Type | Req | Description |
|---|---|---|---|
| seconds | number | yes | Delay duration in seconds. |
No output schema declared.
No examples provided.
device_list ~35
List of Adb Device with state:device Returns: list[dict[str,Any]]: List Adb Device information
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
disconnect ~24
Disconnect from an Android device
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
disconnect_all ~14
Disconnect from all Android devices
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
double_click ~62
Double click at specific coordinates
| Name | Type | Req | Description |
|---|---|---|---|
| duration | number | – | Duration between clicks in seconds, default is 0.1 |
| serial | string | yes | Android device serialno |
| x | integer | yes | X coordinate |
| y | integer | yes | Y coordinate |
No output schema declared.
No examples provided.
drag ~85
Swipe from one point to another point.
| Name | Type | Req | Description |
|---|---|---|---|
| duration | number | – | Duration of drag in seconds, default is 0.5 |
| ex | integer | yes | End X coordinate |
| ey | integer | yes | End Y coordinate |
| serial | string | yes | Android device serialno |
| sx | integer | yes | Start X coordinate |
| sy | integer | yes | Start Y coordinate |
No output schema declared.
No examples provided.
dump_hierarchy ~91
Dump window hierarchy.
| Name | Type | Req | Description |
|---|---|---|---|
| compressed | boolean | – | return compressed xml. |
| max_depth | integer | – | max depth of hierarchy. |
| pretty | boolean | – | pretty print xml. |
| serial | string | yes | Android device serialno. |
| xpath | string | – | optional xpath expression to filter results. If empty, returns the full hierarchy xml. If provided, returns only matching elements, separated by "===". |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
get_orientation ~25
Get current device screen orientation.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
get_toast ~100
Get the most recent Android Toast message from the device. Toast is a brief notification message in the Android system, typically used for operation feedback. This tool uses uiautomator2's built-in toast detection via jsonrpc.getLastToast() which is more reliable than XPath-based UI hierarchy queries.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
| wait_timeout | number | – | Maximum time to wait for a Toast message (seconds). |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
hide_keyboard ~22
Hide keyboard
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
info ~22
Get device info
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
Structured output declared, but exposes no named fields.
No examples provided.
init ~49
Install essential resources (minicap, minitouch, uiautomator ...) to device.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | – | Android device serialno to initialize. If empty string, all devices will be initialized. |
No output schema declared.
No examples provided.
long_click ~64
Long click at specific coordinates
| Name | Type | Req | Description |
|---|---|---|---|
| duration | number | – | Duration of the long click in seconds, default is 0.5 |
| serial | string | yes | Android device serialno |
| x | integer | yes | X coordinate |
| y | integer | yes | Y coordinate |
No output schema declared.
No examples provided.
open_notification ~24
Open the notification panel.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
open_quick_settings ~27
Open the quick settings panel.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
press_key ~81
Press a key
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | Key to press. Supported key name includes: home, back, left, right, up, down, center, menu, search, enter, delete(or del), recent(recent apps), volume_up, volume_down, volume_mute, camera, power |
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
purge ~51
Purge all resources (minicap, minitouch, uiautomator ...) from device.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | – | Android device serialno to purge. If empty string, all devices will be purged. |
No output schema declared.
No examples provided.
read_clipboard ~25
Read clipboard from device
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
reset_toast ~56
Clear the cached Toast message on the device. This resets the Toast message cache on the Android device, allowing you to wait for new Toast messages without interference from previous ones.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
save_dump_hierarchy ~124
Dump window hierarchy and save to file.
| Name | Type | Req | Description |
|---|---|---|---|
| compressed | boolean | – | return compressed xml. |
| file | string | yes | File path to save the hierarchy XML. Supports both absolute and relative paths. |
| max_depth | integer | – | max depth of hierarchy. |
| pretty | boolean | – | pretty print xml. Defaults to True for file output. |
| serial | string | yes | Android device serialno. |
| xpath | string | – | optional xpath expression to filter results. If empty, saves the full hierarchy xml. If provided, saves only matching elements, separated by "===". |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
save_screenshot ~71
Save screenshot of device to file
| Name | Type | Req | Description |
|---|---|---|---|
| display_id | integer | – | Use specific display if device has multiple screens. Defaults to -1 (default display). |
| file | string | yes | File path to save the screenshot. Supports both absolute and relative paths. |
| serial | string | yes | Android device serial number. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
screen_off ~23
Turn screen off
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
screen_on ~23
Turn screen on
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
No output schema declared.
No examples provided.
screen_record ~62
Record screen to file with blocking wait. For non-blocking recording use screen_record_start.
| Name | Type | Req | Description |
|---|---|---|---|
| filename | string | yes | Output file path for the recording. |
| fps | integer | – | Frames per second for recording. |
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
screen_record_start ~62
Start screen recording to file. Runs in background, use screen_record_stop to stop.
| Name | Type | Req | Description |
|---|---|---|---|
| duration | number | yes | Maximum recording duration in seconds. |
| file | string | yes | Output file path for the recording. |
| serial | string | yes | Android device serial number. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
screen_record_stop ~34
Stop screen recording for the device. Stops any active background recording task.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
screenshot ~58
Take screenshot of device
| Name | Type | Req | Description |
|---|---|---|---|
| display_id | integer | – | use specific display if device has multiple screen. Defaults to -1. |
| format | string | – | Image format. Defaults to "jpeg". |
| serial | string | yes | Android device serialno. |
Structured output declared, but exposes no named fields.
No examples provided.
send_text ~50
Send text to the current input field
| Name | Type | Req | Description |
|---|---|---|---|
| clear | boolean | – | – |
| serial | string | yes | Android device serialno |
| text | string | yes | input text clear: clear text before input |
No output schema declared.
No examples provided.
set_focused_text ~88
Set text to the currently focused input element. This method uses device(focused=True).set_text() which calls jsonrpc.setText() directly, bypassing IME requirements. Works on devices with IME restrictions (e.g., OPPO/ColorOS).
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | yes | Android device serialno |
| text | string | yes | Text to set in the focused element |
| Name | Type | Req | Description |
|---|---|---|---|
| result | boolean | yes | – |
No examples provided.
set_orientation ~45
Set device screen orientation.
| Name | Type | Req | Description |
|---|---|---|---|
| orientation | string | yes | Target orientation, one of natural, left, right, upsidedown. |
| serial | string | yes | Android device serial number. |
No output schema declared.
No examples provided.
shell_command ~53
Run a shell command on an Android device
| Name | Type | Req | Description |
|---|---|---|---|
| command | string | yes | Shell command to run |
| serial | string | yes | Android device serialno |
| timeout | number | – | Seconds to wait for command to complete. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
show_toast ~62
Display a Toast message on the Android device.
| Name | Type | Req | Description |
|---|---|---|---|
| duration | number | – | Display duration in seconds (default: 1.0). |
| serial | string | yes | Android device serial number. |
| text | string | yes | The message text to display in the Toast. |
No output schema declared.
No examples provided.
start_scrcpy ~127
Startup scrcpy in background and returns process id. scrcpy is an application mirrors Android devices (video and audio) connected via USB or TCP/IP and allows control using the computer's keyboard and mouse. The scrcpy process will run in the background after successful startup. Use stop_scrcpy to terminate the process.
| Name | Type | Req | Description |
|---|---|---|---|
| serial | string | – | Android device serialno. If empty string, connects to the unique device if only one device is connected. |
| timeout | number | – | Seconds to wait for process to confirm startup. If process is still running after this time, startup is considered successful. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | integer | yes | – |
No examples provided.
What is the UIAutomator2 MCP Server server?
UIAutomator2 MCP Server is listed in the public MCP registry as io.github.tanbro/uiautomator2-mcp-server. Android mobile automation with uiautomator2. AI bot for taps, swipes, apps, XPath testing, RPA. This page covers its PyPI package (uiautomator2-mcp-server).
Is the UIAutomator2 MCP Server server safe to use?
UIAutomator2 MCP Server scores 57 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the UIAutomator2 MCP Server server expose?
UIAutomator2 MCP Server exposes 77 tools: init, purge, shell_command, device_list, connect, and 72 more. Their descriptions and schemas cost roughly 3,851 tokens of context every time the server is loaded.
Is the UIAutomator2 MCP Server server still maintained?
UIAutomator2 MCP Server is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.